Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
270 results
phpunit-brute preview

phpunit-brute

GitHubrandomrobbiebf/phpunit-brute

Tool to try multiple paths for PHPunit RCE CVE-2017-9841

exploitationinformation-gatheringpenetration-testing+3
30
4 years ago
CVE-2023-22518 preview

CVE-2023-22518

GitHubrevoltsecurities/cve-2023-22518

An Exploitation tool to exploit the confluence server that are vulnerable to CVE-2023-22518 Improper Authorization

exploitationinformation-gatheringpenetration-testing+2
432 years ago
strafer preview

strafer

GitHubadityaks/strafer

Strafer: A tool to detect potential infections in Elasticsearch instances

cloud-securitydatabase-securityinformation-gathering+4
275 years ago
melee preview

melee

GitHubadityaks/melee

Python-based tool to detect ransomware infections and malicious code in MySQL instances. Performs reconnaissance, user enumeration, and deep scans…

database-securityincident-responsemalware-analysis+2
233 years ago
regresshion-check preview

regresshion-check

GitHubwiggels/regresshion-check

CLI Tool to Check SSH Servers for Vulnerability to CVE-2024-6387

information-gatheringnetwork-securitypenetration-testing+2
62 months ago
at-doom-fortigate preview

at-doom-fortigate

GitHubjpiechowka/at-doom-fortigate

Fortigate CVE-2018-13379 - Tool to search for vulnerable Fortigate hosts in Rapid7 Project Sonar data anonymously through The Tor network.

exploitationinformation-gatheringnetwork-security+3
52 years ago
CVE-2023-48795 preview

CVE-2023-48795

GitHubtrixsec/cve-2023-48795

A Python-based tool to check for vulnerabilities in OpenSSH installations on local or remote systems by scanning specific IPs. It checks if the…

information-gatheringnetwork-securitypenetration-testing+3
141 year ago
CVE-2023-27163-InternalProber preview

CVE-2023-27163-InternalProber

GitHubsamh4cks/cve-2023-27163-internalprober

A tool to perform port scanning using vulnerable Request-Baskets

exploitationpenetration-testingport-scanning+3
53 years ago
CVE-2025-68461 preview

CVE-2025-68461

GitHubgotr00t0day/cve-2025-68461

A C++ security scanner tool to detect Cross-Site Scripting (XSS) vulnerabilities in Roundcube Webmail installations.

information-gatheringpenetration-testingreconnaissance+3
69 months ago
regreSSHion-Checker preview

regreSSHion-Checker

GitHubm0n3ef/regresshion-checker

A lightweight, fast tool to scan and detect the "regreSSHion" OpenSSH remote code execution vulnerability (CVE-2024-6387).

exploitationinformation-gatheringnetwork-security+3
32 months ago
CVE-2018-7600-Masschecker preview

CVE-2018-7600-Masschecker

GitHubsl4cky/cve-2018-7600-masschecker

Tool to check for CVE-2018-7600 vulnerability on several URLS

exploitationinformation-gatheringpenetration-testing+2
38 years ago
vmxnet3Hunter preview

vmxnet3Hunter

GitHublxkxc/vmxnet3hunter

Use this tool to prioritize cluster patching for the recent VMware advisory VMSA-2018-0027 related to CVE-2018-6981 and CVE-2018-6982.

cloud-infrastructure-securityconfiguration-auditingreconnaissance+2
7 years ago
ICMP-Timestamp-POC preview

ICMP-Timestamp-POC

GitHubransc0rp1on/icmp-timestamp-poc

A reconnaissance tool to detect CVE-1999-0524 (ICMP Timestamp Disclosure) by automating timestamp extraction via nping or hping3. Converts raw ICMP…

exploitationinformation-gatheringnetwork-security+3
1 year ago
CVE-2023-48795 preview

CVE-2023-48795

GitHubhav0cx0/cve-2023-48795

Python tool to identify SSH servers potentially vulnerable to CVE-2023-48795 (Terrapin) by analyzing OpenSSH version banners via netcat. Useful for…

information-gatheringnetwork-securitypenetration-testing+2
1 year ago
nginxpwner preview
Archived

nginxpwner

GitHubstark0de/nginxpwner

Nginxpwner is a simple tool to look for common Nginx misconfigurations and vulnerabilities.

information-gatheringmisconfigurationpenetration-testing+3
1.6k2 years ago
sub404 preview
Archived

sub404

GitHubr3curs1v3-pr0xy/sub404

A python tool to check subdomain takeover vulnerability

dns-analysispenetration-testingreconnaissance+3
3553 years ago
HQLmap preview
Archived

HQLmap

GitHubpaulsec/hqlmap

(Deprecated) HQLmap, Automatic tool to exploit HQL injections

database-securityinformation-gatheringpenetration-testing+2
2286 years ago
routeros-scanner preview

routeros-scanner

GitHubmicrosoft/routeros-scanner

Tool to scan for RouterOS (Mikrotik) forensic artifacts and vulnerabilities.

configuration-auditingdigital-forensicsembedded-systems-security+8
9842 years ago
Previous123…15Next